Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
connect555
New Contributor

DNS Requests -> Forwarding Proxy

Hi, we´re switching from MS FTMG to FortiGate with Explicit Web Proxy and a "Web Proxy Forwarding Server". The MS FTMG sends all DNS-Request to the configured 'Upstream Proxy'. How can i configure this Option on a FortiGate? Opening a Website results in '504 DNS look up failed'. Using a local DNS-Server is not an Option. There is no Webfilter configured.

1 Solution
pavol_jaco
New Contributor II

I have opened ticket for this problem. Guess what... it is normal and as per design :)

Of coarse this is absolutely wrong design. You dont need to resolve anything via DNS when using proxy. As support said, this is simply not yet implemented feature in FortiOS.

View solution in original post

6 REPLIES 6
40netter
New Contributor

Does anybody have a solution to this. We have the exact same problem here. Even though the requests are meant to be forwarded to the parent proxies it seems like the Fortigate tries to do dns resolution on the hostnames, which, ofcourse, fails since the internal DNS server only knows about names in the lan. Any way of disabling dns resolution when forwarding requests would be really helpful.
pavol_jaco
New Contributor II

I have opened ticket for this problem. Guess what... it is normal and as per design :)

Of coarse this is absolutely wrong design. You dont need to resolve anything via DNS when using proxy. As support said, this is simply not yet implemented feature in FortiOS.

connect555

Any update to this behavior?

FortiOS 6.2? mhmh?

sw2090
Honored Contributor

hm you could to two things:

 

a) set the FGT system DNS to your DNS Proxy. Enable DNS Databse Feature on your FGT and configure a DNS Forwarder on the FGT for the interface you need on.

b) let DHCP do it for you. Letzt the FGT be DHCP Server on the interface you need and set the DHCP Server to hand out the proxy as DNS to the Clients.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
fida_khan

Hi All,

 

has anyone found resolution to this issue? if yes then what was the fix as we are currently having the same issue.

 

Regards,

Fida

sw2090
Honored Contributor

as said you can use the FGT as DNS Server for your clients and set the FGT to do DNS forwarding to your proxy.

DNS Forwarding on FortiOS can be configured per interface. The feater in gui is just not enabled by default. So enable "DNS Datbase" in Feature View to have it in gui.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors